Common use of Responsibilities of Business Associate Clause in Contracts

Responsibilities of Business Associate. With regard to its handling of Protected Health Information, the Business Associate hereby agrees to do the following: 3.1 Possess, for the sole purpose of destroying by shredding, the Protected Health Information only as required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report to the Company privacy officer, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement of which Business Associate becomes aware upon the Business Associate’s discovery of such unauthorized use and/or disclosure; 3.3 Use appropriate safeguards to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information; 3.4 Require all of its employees, representatives, subcontractors or agents that receive or have access to Protected Health Information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided. 3.5 Make available, to the Secretary of HHS, all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction of Protected Health Information for purposes of determining the Company’s compliance with the Privacy Rules, subject to attorney-client and other applicable legal privileges. 3.6 Make available, during normal business hours, at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company within thirty (30) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate’s compliance with the terms of this Agreement; 3.7 Within thirty (30) days of receiving a written request from The Company, provide to the Company such information as is requested by The Company to permit the Company to respond to any request for accounting for any disclosures of an individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 Return to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate’s possession on the date of such request and retain no copies; and 3.9 Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement or the Service Agreement.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling If, during the term of Protected Health Informationthis Agreement, the Business Associate is in receipt of PHI, Business Associate hereby agrees to do the following: 3.1 Possess, for a. Use and/or disclose the sole purpose of destroying by shredding, the Protected Health Information PHI only as permitted or required by the Service Agreement, this Agreement or as otherwise required Required by law;Law. 3.2 Immediately report b. Report to the Company privacy officerdesignated Privacy and Security Officer of FMCNA, in writing, any other use and/or disclosure of the Protected Health Information PHI that is not permitted or required by this the Agreement of which Business Associate becomes aware upon the within two (2) days of Business Associate’s discovery of such unauthorized use and/or disclosure;. 3.3 c. Establish procedures for mitigating, to the greatest extent possible, any deleterious effects from any improper use and/or disclosure of PHI that Business Associate reports to FMCNA. d. Use appropriate safeguards to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information;PHI. 3.4 e. Implement Administrative, Physical, and Technical safeguards that reasonably and appropriately protect the Confidentiality, Integrity and Availability of the Electronic PHI that Business Associate creates, receives, maintains, or transmits on behalf of FMCNA. f. Require all of its employees, representatives, subcontractors or and agents that receive create, receive, maintain, transmit, use, or have access to Protected Health Information under to, PHI governed by this Agreement to agree agree, in writing writing, to adhere to the same restrictions and conditions on the use use, disclosure, and/or disclosure protection of Protected Health Information PHI that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter providedBusiness Associate pursuant hereto. 3.5 g. Make available, to the Secretary of HHS, available all records, books, agreements, policies policies, procedures, and procedures internal practices relating to the document destruction services provided by Business Associate in use and/or disclosure of PHI to the services provided to The Company involving the handling United States Secretary of Health and distraction of Protected Health Information Human Services for purposes of determining the CompanyFMCNA’s compliance with the Privacy RulesHIPAA, subject to attorney-client and other applicable legal privileges. 3.6 Make available, during normal business hours, at Business Associate’s offices all records, books, agreements, policies and procedures relating to i. Upon termination of the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, where feasible, destroy or return to the Company FMCNA within thirty (30) days all PHI received from, or created, received, maintained or transmitted by Business Associate on behalf of The Company's written requestFMCNA. Where return or destruction is not feasible, for the purpose duties of enabling Business Associate under this Agreement shall be extended to protect the Company to verify the PHI retained by Business Associate. Business Associate agrees to limit further uses and disclosures of the PHI retained to those purposes that made the return or destruction infeasible. j. Disclose to its subcontractors, agents or other third parties, and request from FMCNA, only the minimum PHI necessary to perform or fulfill a specific function required or permitted hereunder. k. Notify FMCNA within two (2) business days if an Individual (FMCNA patient or the patient’s compliance legal representative) wishes to assert his or her right of access to obtain a copy of PHI as set forth in 45 C.F.R. § 164.524. l. At the request of FMCNA, and in the time and manner specified by FMCNA, provide access to PHI contained in a Designated Record Set to an Individual in accordance with the terms and provisions of this Agreement;45 C.F.R. § 164.524. FMCNA’s determination of what constitutes PHI or a Designated Record Set shall be final and conclusive. 3.7 Within thirty m. Notify FMCNA within two (302) business days if an Individual (FMCNA patient or the patient’s legal representative) wishes to assert his or her right to amend PHI or amend a record in a Designated Record Set as set forth in 45 C.F.R. § 164.526. n. Make any amendment(s) to an Individual’s PHI contained in a Designated Record Set that FMCNA directs or agrees to pursuant to 45 C.F.R. § 164.526 and in the time and manner directed by FMCNA. FMCNA’s determination of receiving a written request from The Company, provide what PHI is subject to amendment pursuant to 45 C.F.R. § 164.526 shall be final and conclusive. o. Notify FMCNA within two (2) business days if an Individual (FMCNA patient or the Company such information patient’s legal representative) wishes to assert his or her right to receive an accounting of disclosures of PHI as is requested by The Company to permit the Company set forth in 45 C.F.R. § 164.528. p. Document any disclosures of PHI that would be required for FMCNA to respond to any a request by an Individual for an accounting for any of disclosures of an individual’s Protected Health Information PHI in accordance with 45 C.F.R. §164.526 and §§ 164.528; 3.8 Return to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate’s possession on the date of such request and retain no copies; and 3.9 . Business Associate agrees to mitigateprovide to FMCNA, in a time and manner designated by FMCNA, the information collected in accordance with this paragraph to permit FMCNA respond to a request by an Individual for an accounting of disclosures pursuant to 45 C.F.R. § 164.528. q. Report in writing, within two (2) days, to the extent practicable, FMCNA any harmful effect that is known to Security Incident (as defined in 45 C.F.R. § 164.304) of which Business Associate of an unauthorized use or disclosure of Protected Health Information by becomes aware. However, the obligation to report a Security Incident shall not include immaterial incidents, such as unsuccessful attempts to penetrate Business Associate in violation of the requirements of this Agreement or the Service AgreementAssociate’s information system.

Appears in 1 contract

Sources: Transfer and Administration Agreement (Fresenius Medical Care AG & Co. KGaA)

Responsibilities of Business Associate. With regard to its handling use and disclosure of Protected Health Informationprotected health information, the Business Associate hereby BUSINESS ASSOCIATE agrees to do the following: 3.1 Possess, for : Use and/or disclose the sole purpose of destroying by shredding, the Protected Health Information protected health information only as required permitted by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report ; no further use or disclosure is permitted. Use appropriate physical, technical and administrative safeguards to protect electronic PHI, and comply with the requirements of the HIPAA Security Regulations (45 CFR Part 164 Subpart C) which are applicable to business associates. Report to the Company privacy officerCOVERED ENTITY any security incident, and any use or disclosure not provided by this contract, including breaches of unsecured protected health information as required by 45 CFR 164.410. Require that subcontractors who create, receive, maintain or transmit ePHI on behalf of Business Associate comply with applicable HIPAA Security regulations by entering into a Business Associate contract with these subcontractors. The Business Associate contract shall meet the specifications of 45 CFR 164.314. Make available to the individual any requested protected health information, in writingaccordance with procedures specified by COVERED ENTITY and in compliance with 45 CFR 164.524, “Access of individuals to protected health information”. Make available for amendment and incorporate any other use and/or disclosure amendments to protected health information in accordance with the requirements of 45 CFR 164.526, “Amendment of protected health information”. Make available the information required to provide an accounting of disclosures in accordance with 45 CFR 164.528. To the extent that BUSINESS ASSOCIATE is to carry out COVERED ENTITY’s obligations under the HIPAA Privacy Regulations, 45 CFR 164 Part E, comply with the requirements of the Protected Health Information that is not permitted or required by this Agreement Privacy Regulations in the performance of which Business Associate becomes aware upon the Business Associate’s discovery of such unauthorized use and/or disclosure; 3.3 Use appropriate safeguards to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information; 3.4 Require all of its employees, representatives, subcontractors or agents that receive or have access to Protected Health Information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided. 3.5 those obligations. Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in use and/or disclosure of protected health information to the services provided to The Company involving the handling and distraction Secretary of Protected Health Information HHS for purposes of determining the CompanyCOVERED ENTITY’s compliance with the Privacy RulesHIPAA regulations, subject to attorney-client and other applicable legal privileges. 3.6 Make available, during normal business hours, at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company within thirty (30) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate’s compliance with the terms of this Agreement; 3.7 Within thirty (30) days of receiving a written request from The Company, provide to the Company such information as is requested by The Company to permit the Company to respond to any request for accounting for any disclosures of an individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 . Return to the Company COVERED ENTITY or immediately destroy, as requested by the CompanyCOVERED ENTITY, any Protected Health Information provided to Business Associatewithin 30 days of the termination of this Agreement, that is the protected health information in Business AssociateBUSINESS ASSOCIATE’s possession on the date of such request and retain no copies or electronic back-up copies; and 3.9 Business Associate agrees to mitigate. If this is not feasible, BUSINESS ASSOCIATE will limit further uses and disclosures to the extent practicablereason that return/destruction is not feasible, any harmful effect that and to extend the protections in this agreement for as long as the protected health information is known to Business Associate of an unauthorized use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement or the Service Agreementits possession.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling use and/or disclosure of Protected Health Information, the Business Associate hereby agrees to do the following: 3.1 Possess, for the sole purpose of destroying by shredding, a. Use and/or disclose the Protected Health Information only as permitted or required by the Service Agreement, this Agreement or as otherwise required by law;. 3.2 Immediately report b. Report to the Company privacy officerdesignated Privacy Officer of Covered Entity, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement of which Business Associate becomes aware upon the within a reasonable time of Business Associate’s discovery of such unauthorized use and/or disclosure;. 3.3 c. Establish procedures for mitigating, to the greatest extent possible, any effects from any improper use and/or disclosure of Protected Health Information that Business Associate reports to Covered Entity. d. Use appropriate safeguards commercially reasonable efforts to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information;. 3.4 e. Require all of its employees, representatives, subcontractors or and agents that receive or use, or have access to to, Protected Health Information under this Agreement to agree agree, in writing writing, to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter providedBusiness Associate pursuant to this Agreement. 3.5 f. Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction use and/or disclosure of Protected Health Information to the Secretary of HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy RulesRegulation, subject to attorney-client and other applicable legal privileges. 3.6 Make available, during normal business hours, at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company within thirty (30) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate’s compliance with the terms of this Agreement; 3.7 g. Within thirty (30) 45 days of receiving a written request from The CompanyCovered Entity, provide to the Company Covered Entity such information as is requested by The Company Covered Entity to permit the Company Covered Entity to respond to any a request by an individual for an accounting for any of the disclosures of an the individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528;HIPAA. 3.8 Return h. Subject to the Company Section 4.4 below, return to Covered Entity or immediately destroy, as requested by within a reasonable time of the Companytermination of this Agreement, any the Protected Health Information provided to Business Associate, that is in Business Associate’s its possession on the date of such request and retain no copies; andcopies (which for purposes of this Agreement shall mean destroy all backup tapes).‌‌‌‌‌‌‌‌‌‌ 3.9 Business Associate agrees i. Disclose to mitigateits subcontractors, to agents or other third parties, and request from Covered Entity, only the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of minimum Protected Health Information by Business Associate in violation of the requirements of this Agreement necessary to perform or the Service Agreementfulfill a specific function required or permitted hereunder.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to Regarding its handling use and/or disclosure of Protected Health Information, the Business Associate hereby agrees to do the following: 3.1 Possess, for the sole purpose of destroying by shredding, A. Use and/or disclose the Protected Health Information in its possession only as required permitted by the Service Agreement, this Agreement HIPAA exhibit or as otherwise required by law; 3.2 Immediately report to the Company privacy officer, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement of which Business Associate becomes aware upon the Business Associate’s discovery of such unauthorized use and/or disclosurefederal and state laws; 3.3 Use appropriate safeguards to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information; 3.4 Require B. Ensure that all of its employees, representatives, subcontractors subcontractors, or agents that receive receive, use, or have access to Protected Health Information under this Agreement HIPAA exhibit agree to agree in writing to adhere to comply with the same restrictions terms and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return return, destroy, or destroy maintain the confidentiality of Protected Health Information as provided under Section 8(B)(2) of this HIPAA exhibit; C. Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Protected Health Information that it creates, receives, maintains, or transmits on behalf of the Covered Entity, as hereinafter provided.required by the Privacy and Security Rule; 3.5 Make available, to the Secretary of HHS, all records, books, agreements, policies and D. Establish procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction for mitigating improper use and/or disclosure of Protected Health Information in the event Business Associate discloses Protected Health Information to any third party for purposes of determining the Company’s compliance with other than “treatment,” “payment,” or “health care operations,” as those terms are used and defined within the Privacy Rules, subject and Security Rule. Business Associate shall provide prompt notice of the date and purpose of each disclosure as well as the name and address of the recipient to attorney-client and other applicable legal privilegesthe Covered Entity at the address set forth in the licensing Agreement. 3.6 Make availableE. Report to the designated Privacy Officer of Covered Entity in writing any use and/or disclosure of the Protected Health Information that is not permitted or required by this HIPAA exhibit or a security incident of which Business Associate becomes aware of within ten (10) days of Business Associate’s discovery of such unauthorized use and/or disclosure or security incident; F. Upon written request, make available during normal business hours, hours at Business Associate’s offices all records, books, agreements, policies policies, and procedures relating to the use, destruction, use and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company Covered Entity within thirty ten (3010) days of The Company's written request, receiving the request for the purpose purposes of enabling the Company Covered Entity to verify the determine Business Associate’s compliance with the terms of this AgreementHIPAA exhibit; 3.7 G. Make available all records, books, agreements, policies, and procedures relating to the use and/or disclosure of Protected Health Information to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy and Security Rule, subject to attorney-client privilege and other applicable legal privileges; and H. Within thirty (30) days of receiving a written request from The CompanyCovered Entity, provide to the Company Covered Entity such information as is requested by The Company Covered Entity to permit the Company Covered Entity to respond to any a request by an Individual to account for accounting for any disclosures of an individualthe Individual’s Protected Health Information or to amend the Individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 Return to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate’s possession on the date of such request and retain no copies; and 3.9 Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of Protected Health Information by Business Associate in violation of the requirements Section 7 of this Agreement or the Service AgreementHIPAA exhibit.

Appears in 1 contract

Sources: Software as a Service Master License Agreement and Master Service Agreement

Responsibilities of Business Associate. With regard to its handling use and/or disclosure of Protected Health Information, the Business Associate hereby agrees to do the following: 3.1 Possess, for the sole purpose of destroying by shredding, : Use and/or disclose the Protected Health Information only as permitted or required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report . Report to the Company privacy officerdesignated Privacy Officer of Covered Entity, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement and as required by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) and its implementing regulations, of which Business Associate becomes aware upon the within 10 days of Business Associate’s discovery of such unauthorized use and/or disclosure; 3.3 . Establish procedures for mitigating, to the greatest extent possible, any effects from any improper use and/or disclosure of Protected Health Information that Business Associate reports to Covered Entity. Use appropriate safeguards commercially reasonable efforts to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information; 3.4 . Require all of its employees, representatives, subcontractors or and agents that receive or use, or have access to to, Protected Health Information under this Agreement to agree agree, in writing writing, to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided. 3.5 Business Associate pursuant this Agreement. Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction use and/or disclosure of Protected Health Information to the Secretary of HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy RulesRegulation, subject to attorney-client and other applicable legal privileges. 3.6 Make available. Upon prior written request, make available during normal business hours, hours at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, use and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company Covered Entity within thirty (30) 15 days of The Company's written request, for the purpose purposes of enabling the Company Covered Entity to verify the determine Business Associate’s compliance with the terms of this Agreement; 3.7 . Within thirty (30) 45 days of receiving a written request from The CompanyCovered Entity, provide to the Company Covered Entity such information as is requested by The Company Covered Entity to permit the Company Covered Entity to respond to any a request by an individual for an accounting for any of the disclosures of an the individual’s 's Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 Return HIPAA. Subject to the Company Section 4.5 below, return to Covered Entity or immediately destroy, as requested by within 15 days of the Companytermination of this Agreement, any the Protected Health Information provided to Business Associate, that is in Business Associate’s its possession on the date of such request and retain no copies; and 3.9 Business Associate agrees copies (which for purposes of this Agreement shall mean destroy all backup tapes). Disclose to mitigateits subcontractors, to agents or other third parties, and request from Covered Entity, only the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of minimum Protected Health Information by Business Associate in violation of the requirements of this Agreement necessary to perform or the Service Agreementfulfill a specific function required or permitted hereunder.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling use or disclosure of Protected Health Information, the Business Associate hereby agrees to do the followingthat it shall: 3.1 Possess, for the sole purpose of destroying by shredding, (a) Use or disclose the Protected Health Information only as required by needed to perform its obligations to the Covered Entity under the Service Agreement, provided that such use or disclosure would not violate the HIPAA Rules if done by the Covered Entity; (b) Not use or further disclose Protected Health Information other than as permitted or required by this Addendum, the Service Agreement or as otherwise required by law; 3.2 Immediately report (c) Use appropriate safeguards to prevent unauthorized use or disclosure of such Protected Health Information; (d) Mitigate, to the Company privacy officerextent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Addendum; (e) Report to the designated Compliance Officer of the Covered Entity, in writing, (i) any other use and/or disclosure Use or Disclosure of the Protected Health Information that is not permitted or required by this Agreement Addendum and (ii) any Security Incident of which Business Associate becomes aware upon within ten (10) days of the Business Associate’s discovery of such unauthorized use and/or disclosureUse or Disclosure or Security Incident; 3.3 Use appropriate safeguards to maintain (f) To the security extent that any of the Protected Health Information Used and/or Disclosed by the Business Associate constitutes Personal Information, the Business Associate shall notify affected Individuals of any Security Breach in the manner required by and pursuant to prevent unauthorized use and/or disclosure the provisions of such Protected Health InformationNew Hampshire RSA 359-C:20 and otherwise comply with the requirements of RSA 359-C; 3.4 (g) Require all of its employees, representatives, subcontractors or agents that receive or use or have access to Protected Health Information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use Use and/or disclosure Disclosure of Protected Health Information that apply as are contained herein; (h) Provide access, including at the obligation request of Covered Entity, and in the time and manner designated by Covered Entity, to return or destroy the Protected Health Information as hereinafter provided. 3.5 Make availablein a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the Secretary requirements under 45 CFR 164.524; (i) Make any amendment(s) to Protected Health Information in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR 164.526 at the request of HHSCovered Entity or an Individual, and in the time and manner designated by Covered Entity; (j) Document such disclosures of Protected Health Information and information related to such disclosures as would be required for the Covered Entity to respond to a request by an Individual for an accounting of disclosures in accordance with 45 C.F.R. §164.528; (k) Make available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction use and/or disclosure of Protected Health Information to the Covered Entity, or at the request of the Covered Entity to the Secretary of HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy HIPAA Rules; (l) Upon written request, subject to attorney-client and other applicable legal privileges. 3.6 Make available, make available during normal business hours, hours at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, Use and/or disclosure Disclosure of Protected Health Information that is subject to this Agreement, to the Company Covered Entity within thirty (30) days of The Company's written request, for the purpose purposes of enabling the Company Covered Entity to verify determine the Business Associate’s compliance with the terms of this AgreementAddendum; 3.7 Within (m) Return to the Covered Entity or destroy, as requested by the Covered Entity, within thirty (30) days of receiving a written request from The Companythe expiration or termination of this Addendum, provide to the Company such information as is requested by The Company to permit the Company to respond to any request for accounting for any disclosures of an individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 Return to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate’s possession on the date of such request and retain no copiescopies or back-ups of any kind; and 3.9 Business Associate agrees to mitigate(n) Implement administrative, to physical and technical safeguards that reasonably and appropriately protect the extent practicableconfidentiality, any harmful effect that is known to Business Associate integrity, and availability of an unauthorized use or disclosure of the Electronic Protected Health Information by that the Business Associate in violation Uses and/or Discloses on behalf of the requirements of this Agreement or the Service AgreementCovered Entity.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling use of Protected Health Informationprotected health information, the Business Associate hereby agrees to do the following: 3.1 Possess, for (a) Use the sole purpose of destroying by shredding, the Protected Health Information protected health information only as permitted or required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report (b) Report to the Company designated privacy officerofficer of the Covered Entity, in writing, any other use and/or disclosure of the Protected Health Information protected health information that is not permitted or required by this Agreement of which Business Associate becomes aware upon within fifteen (15) days of the Business Associate’s discovery of such unauthorized use and/or disclosureuse; 3.3 (c) Use appropriate safeguards to maintain the security prevent use or disclosure of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Informationprotected health information other than as provided by this Agreement; 3.4 (d) Require all of its employees, representatives, subcontractors or agents that receive or use or have access to Protected Health Information protected health information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information protected health information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided.protected health information; 3.5 (e) Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in use and/or disclosure of protected health information to the services provided to The Company involving the handling and distraction Secretary of Protected Health Information HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy Rules, subject Regulation; (f) Business Associate agrees to attorney-client document disclosures of protected health information and other applicable legal privilegesinformation related to such disclosures as would be required for the Covered Entity to respond to a request by an individual for an accounting of disclosures of protected health information in accordance with 45 C.F.R §164.528. 3.6 Make available(g) Business Associate agrees to make any amendment(s) to protected health information in a designated record set that the Covered Entity directs or agrees to pursuant to 45 C.F.R §164.526 at the request of the Covered Entity or an individual, during normal business hoursand in a reasonable time an manner. (h) Business Associate agrees to provide access, at Business Associate’s offices all recordsthe request of the Covered Entity, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreementin a reasonable time and manner, to protected health information in a designated record set, to Covered Entity or, as directed by Covered Entity, to an individual in order to meet the Company within thirty requirement under 45 C.F.R §164.524. (30i) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate’s compliance with the terms of this Agreement; 3.7 Within thirty forty five (3045) days of receiving a written request from The Companythe Covered Entity, provide to the Company Covered Entity such information as is requested by The Company the Covered Entity to permit the Company Covered Entity to respond to any a request by the subject individual for amendment and accounting for any purposes of the disclosures of an the individual’s Protected Health Information protected health information in accordance with 45 C.F.R. §164.526 and §164.528. Covered Entity shall reimburse Business Associate for reasonable fees associated with providing said information; 3.8 (j) Return to the Company Covered Entity or immediately destroy, as requested by the CompanyCovered Entity, any Protected Health Information provided to Business Associatewithin thirty (30) days of the termination of this Agreement, that is the protected health information in Business Associate’s possession on the date of such request and retain no copies; and 3.9 . Upon a determination by the Business Associate agrees to mitigatethat return or destruction of protected health information is infeasible, to the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of Protected Health Information by Business Associate in violation of shall extend the requirements protections of this Agreement to such protected health information and limit further uses and disclosures of such protected health information to those purposes that make the return or the Service Agreementdestruction infeasible for so long as Business Associate maintains such protected health information.

Appears in 1 contract

Sources: Non Exclusive License Agreement

Responsibilities of Business Associate. With regard to its handling use and/or disclosure of Protected Health Informationprotected health information, the Business Associate hereby agrees to do the following: 3.1 Possess, for (a) Use and/or disclose the sole purpose of destroying by shredding, the Protected Health Information protected health information only as permitted or required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report (b) Report to the Company designated privacy officerofficer of the Covered Enti ty, in writing, any other use and/or disclosure of the Protected Health Information protected health information that is not permitted or required by this Agreement of which Business Associate becomes aware upon within fifteen (15) days of the Business Associate’s discovery of such unauthorized use and/or disclosure; 3.3 (c) Use appropriate safeguards commercially reasonable efforts to maintain the security of the Protected Health Information protected health information and to prevent unauthorized use and/or disclosure of such Protected Health Informationprotected health information; 3.4 (d) Require all of its employees, representatives, subcontractors or agents that receive or use or have access to Protected Health Information protected health information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information protected health information that apply herein, including the obligation to return or destroy the Protected Health Information protected health information as hereinafter providedprovided under (h) of this section. 3.5 (e) Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in use and/or disclosure of protected health information to the services provided to The Company involving the handling and distraction Secretary of Protected Health Information HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy RulesRegulation, subject to attorney-client and other applicable legal privileges. 3.6 Make available(f) Upon written request, make available during normal business hours, hours at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, use and/or disclosure of Protected Health Information that is subject to this Agreement, protected health information to the Company Covered Entity within thirty fifteen (3015) days of The Company's written request, for the purpose purposes of enabling the Company Covered Entity to verify determine the Business Associate’s compliance with the terms of this Agreement; 3.7 (g) Within thirty forty five (3045) days of receiving a written request from The Companythe Covered Entity, provide to the Company Covered Entity such information as is requested by The Company the Covered Entity to permit the Company Covered Entity to respond to any a request by the subject individual for amendment and accounting for any purposes of the disclosures of an the individual’s Protected Health Information protected health information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 (h) Return to the Company Covered Entity or immediately destroy, as requested requ ested by the CompanyCovered Entity, any Protected Health Information provided to Business Associatewithin fifteen (15) days of the termination of this Agreement, that is the protected health information in Business Associate’s possession on the date of such request and retain no copiescopies or back-up tapes; and 3.9 (i) Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of an unauthorized a use or disclosure of Protected Health Information protected health information by Business Associate in violation of the requirements of this Agreement or the Service Agreement.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling of Protected Health Information, the Business Associate hereby agrees to do the followingwill: 3.1 Possess, for the sole purpose of destroying by shredding, the (a) Not use or further disclose Protected Health Information only other than as required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report to the Company privacy officer, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement of which Business Associate becomes aware upon the Business Associate’s discovery of such unauthorized use and/or disclosureOriginal Contract or as required by law, including without limitation, the Privacy Regulations and any applicable State law; 3.3 (b) Use appropriate safeguards to maintain the security prevent use or disclosure of the Protected Health Information other than as provided for in the Original Contract; (c) Implement administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of the electronic protected health information that it creates, receives, maintains, or transmits on behalf of the Covered Entity. (d) Report to prevent unauthorized Covered Entity any use and/or or disclosure of such Protected Health Information; 3.4 Require all of its employees, representatives, subcontractors or agents that receive or have access to Protected Health Information under this Agreement not provided for in the Original Contract of which it becomes aware; (e) Ensure that any agents, including a subcontractor, to agree in writing to adhere whom it provides Protected Health Information received from, or created or received by Business Associate on behalf of, the Covered Entity aggrees to the same restrictions and conditions on the use and/or disclosure of that apply to Business Associate with respect to Protected Health Information. Further any agent or subcontractor must agree to implement reasonable and appropriate safeguards to protect electronic protected health information. (f) Make available for inspection and copying Protected Health Information that apply herein, including the obligation to return or destroy the an individual about such individual in accordance with 45 C.F.R § 164.524; (g) Make available Protected Health Information as hereinafter provided. 3.5 Make available, to the Secretary of HHS, all records, books, agreements, policies an individual about such individual for amendment and procedures relating incorporate any amendments to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction of Protected Health Information for purposes of determining the Company’s compliance with the Privacy Rules, subject to attorney-client and other applicable legal privileges. 3.6 Make available, during normal business hours, at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company within thirty (30) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate’s compliance with the terms of this Agreement; 3.7 Within thirty (30) days of receiving a written request from The Company, provide to the Company such information as is requested by The Company to permit the Company to respond to any request for accounting for any disclosures of an individual’s Protected Health Information in accordance with 45 C.F.R. §164.526 and § 164.526; (h) Make available Protected Health Information required to provide an accounting of disclosures in accordance with 45 C.F.R. §164.528; 3.8 Return (i) Make its internal practices, books, and records relating to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate’s possession on the date of such request and retain no copies; and 3.9 Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of use an unauthorized use or disclosure of Protected Health Information received from, or created or received by Business Associate in violation on behalf of, Covered Entity available to the Secretary of HHS to whom the authority involved has been delegated for purposes of determining the Covered Entity’s compliance with privacy Regulations; and (j) At termination of the requirements Original Contract, if feasible, return all Protected Health Information received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associates still maintains in any form and retain no copies of such Protected Health information or, if return is not feasible, extend the protections of the Original Contract and this Agreement or to the Service Agreementinformation and limit further uses and disclosures to those purposes that make the return of the protected Health Information infeasible.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to its handling use and/or disclosure of Protected Health Information, the Business Associate hereby agrees to do the following: 3.1 Possess, for the sole purpose of destroying by shredding, : Use and/or disclose the Protected Health Information only as permitted or required by the Service Agreement, this Agreement or as otherwise required by law; 3.2 Immediately report . Report to the Company privacy officerdesignated Privacy Officer of Covered Entity, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement and as required by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) and its implementing regulations, of which Business Associate becomes aware upon the within 10 days of Business Associate’s discovery of such unauthorized use and/or disclosure; 3.3 . Establish procedures for mitigating, to the greatest extent possible, any effects from any improper use and/or disclosure of Protected Health Information that Business Associate reports to Covered Entity. Use appropriate safeguards commercially reasonable efforts to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information; 3.4 . Require all of its employees, representatives, subcontractors or and agents that receive or use, or have access to to, Protected Health Information under this Agreement to agree agree, in writing writing, to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided. 3.5 Business Associate pursuant this Agreement. Make available, to the Secretary of HHS, available all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction use and/or disclosure of Protected Health Information to the Secretary of HHS for purposes of determining the CompanyCovered Entity’s compliance with the Privacy RulesRegulation, subject to attorney-client and other applicable legal privileges. 3.6 Make available. Upon prior written request, make available during normal business hours, hours at Business Associate’s offices all records, books, agreements, policies and procedures relating to the use, destruction, use and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company Covered Entity within thirty (30) 15 days of The Company's written request, for the purpose purposes of enabling the Company Covered Entity to verify the determine Business Associate’s compliance with the terms of this Agreement; 3.7 . Within thirty (30) 45 days of receiving a written request from The CompanyCovered Entity, provide to the Company Covered Entity such information as is requested by The Company Covered Entity to permit the Company Covered Entity to respond to any a request by an individual for an accounting for any of the disclosures of an the individual’s 's Protected Health Information in accordance with 45 C.F.R. §164.526 and §164.528; 3.8 Return HIPAA. Subject to the Company Section 4.4 below, return to Covered Entity or immediately destroy, as requested by within 15 days of the Companytermination of this Agreement, any the Protected Health Information provided to Business Associate, that is in Business Associate’s its possession on the date of such request and retain no copies; and 3.9 Business Associate agrees copies (which for purposes of this Agreement shall mean destroy all backup tapes). Disclose to mitigateits subcontractors, to agents or other third parties, and request from Covered Entity, only the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of minimum Protected Health Information by Business Associate in violation of the requirements of this Agreement necessary to perform or the Service Agreementfulfill a specific function required or permitted hereunder.

Appears in 1 contract

Sources: Business Associate Agreement